AI Incident Intelligence

Rite Aid facial recognition produced thousands of false-positive matches

The FTC alleged Rite Aid deployed AI-based facial recognition without reasonable safeguards and that the system generated thousands of false-positive matches, with disproportionate risks in some communities.

criticalRite Aidbiometric surveillanceUnited States

Impact

Rite Aid agreed to a five-year prohibition on using facial recognition for surveillance purposes and other safeguards, subject to court approval processes described by the FTC.

Contributing factors

The FTC alleged insufficient accuracy testing, risk assessment, consumer notice, vendor oversight and data-security controls.

Response

Five-year surveillance ban, comprehensive safeguards, information-security programme and oversight requirements.

Assurance lesson

This record should inform control design, testing and monitoring for comparable AI systems. The incident database does not infer that every system using the same provider or model shares the same failure.

Control lessons

Assurance controls implicated by this incident pattern.

These are CRG methodology mappings from the documented incident to controls worth testing in comparable systems. They do not assert that any single control would have prevented the incident.

RISK-04

Impact assessment

Material impacts on users, workers, customers or the public are assessed.

DATA-02

Sensitive data controls

Personal, confidential and regulated data is protected in AI workflows.

DATA-05

Privacy rights readiness

Relevant privacy rights and deletion/correction processes extend to AI-enabled processing.

FAIR-01

Affected-group analysis

Materially affected groups and differential risks are identified.

FAIR-02

Bias and disparity evaluation

Where relevant, outcome disparities are measured using appropriate metrics.

Evidence

Source provenance is part of the incident record.

U.S. Federal Trade Commission · confidence 99% · last verified 23 Aug 2026

Open underlying source